CNCERT warns of FlyLegit: protect hosts from becoming attack nodes

Review remote management, unexpected outbound traffic and recovery on Linux and IoT devices.

Contents of this article

What the notice reports

CNCERT’s September 30, 2026 notice reports joint monitoring with NSFOCUS of FlyLegit spreading to Linux and IoT devices and using them for DDoS. Operators should examine unauthorized outbound activity as well as incoming attacks.

Start with management exposure

Review exposed management services, default accounts, old firmware and neglected edge devices. Assign owners and update paths, restrict access where upgrades are delayed, and plan replacement. Avoid shared management passwords across fleets.

Correlate egress with expected workloads

Compare unfamiliar destinations, idle-time packet bursts and recurring unknown processes with scheduled work. These symptoms alone do not identify FlyLegit; correlate published indicators with host and network evidence.

Recovery must prevent reinfection

Contain unnecessary connectivity and preserve evidence before cleaning or rebuilding from trusted media. Fix the entry weakness, rotate affected credentials and observe egress. Killing a process or protecting the public service alone does not recover a compromised device.

References

CNCERT FlyLegit notice

Continue reading

Read related content

Back to industry insights Contact technical support